Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Air-gapped deployment

    Running with no internet anywhere in the loop.

    MangoFly runs entirely inside a disconnected network. The differences from a standard install are all in how TLS is obtained and trusted.

    TLS without ACME

    With no internet there is no ACME challenge, so the server terminates TLS itself from operator-supplied PEM files. Either issue a certificate from your own CA, or have the server mint a self-signed one for the names and addresses clients will actually use.

    mangofly-server --generate-selfsigned --san mesh.internal,10.20.0.5

    Trusting it

    • Clients get the certificate or your CA — As a custom trust root, additive to the system store rather than replacing it.
    • Names must match — Clients reach the server by a name or address in the certificate's SAN set.
    • No escape hatch — Hostname verification always runs. There is deliberately no skip-verification option anywhere in the product.

    What already needed no internet

    • NAT traversal — Uses only the server's own UDP reflector. There is no public STUN fallback to forget to block.